Nalu AI

Privacy

This privacy policy explains the nature, scope and purpose of personal-data processing on this website. We take privacy seriously — and not just because the GDPR requires us to.

1. Controller

Controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR):

Maximilian Fischer
Liebenzeller Straße 50
75339 Höfen an der Enz
Germany

Phone: +49 151 11637402
Email: hello@nalu-ai.com

2. Hosting and server log files

This website is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). On every request, technically necessary data (date/time of the request, IP address, user agent, referrer, URL accessed) is automatically processed by our hosting provider in server log files.

Processing serves to provide and secure the service on the basis of Art. 6 (1) (f) GDPR (legitimate interest in stable, secure operation). A data processing agreement (Art. 28 GDPR) is in place with Vercel. Data transfer to the USA takes place on the basis of the EU-US Data Privacy Framework or, supplementarily, on Standard Contractual Clauses (Art. 46 (2) (c) GDPR).

Log file data is stored for a maximum of 30 days and then deleted automatically.

3. Web analytics with Plausible

We use Plausible Analytics to statistically evaluate visits. Plausible does not use cookies and does not collect personal data. IP addresses are not stored; they are only used briefly to compute an anonymized daily hash.

Only aggregated statistics are recorded — page views, dwell time, country of origin and referrer. There is no recognition across devices or sessions.

Legal basis is Art. 6 (1) (f) GDPR. As no cookies are set and no personal data is processed, no consent is required. Provider: Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia.

4. Cookies

This website does not set any tracking or marketing cookies. Only technically necessary storage mechanisms required to operate the website are used. Consent via a cookie banner is therefore not required.

5. Retention periods

Personal data is only stored for as long as necessary for the respective purpose or as required by statutory retention periods. Specifically:

• Server log files: 30 days
• Inquiry data without follow-up business: up to 6 months
• Business correspondence: 6 years (§ 257 HGB)
• Tax-relevant documents: 10 years (§ 147 AO)

6. Your rights as a data subject

You have the right at any time to:

• Access information about the data stored about you (Art. 15 GDPR)
• Rectification of inaccurate data (Art. 16 GDPR)
• Erasure of your data (Art. 17 GDPR)
• Restriction of processing (Art. 18 GDPR)
• Data portability (Art. 20 GDPR)
• Objection to processing (Art. 21 GDPR)
• Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)

An informal notice to the contact details given in the imprint is sufficient to exercise your rights.

7. Right to lodge a complaint

You have the right to lodge a complaint with a data-protection supervisory authority about the processing of your personal data. The competent authority is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de

8. Changes to this policy

We reserve the right to adjust this privacy policy so that it always meets current legal requirements or to reflect changes in our processing operations. The version current at the time of your next visit applies.

As of: May 2026